Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

China-linked Jewelbug group conducts espionage and cryptocurrency theft

The China-linked Jewelbug APT group conducts espionage and cryptocurrency theft using a custom C2 panel and three primary implants: Antino (Windows backdoor), ClientKing (Linux backdoor), and a malicious "PDF Viewer" browser extension capable of stealing credentials, sessions, and manipulating crypto transactions. The group compromises government, military, telecom, and industrial targets while also running fraudulent crypto and betting websites. Its scale and targets suggest it operates on behalf of or in collaboration with a Chinese state agency.
Read Full Article →

Threat Intelligence China-linked Jewelbug group conducts espionage and cryptocurrency theft August 13, 2026 Share By SC Staff (Adobe Stock) A mercenary advanced persistent threat (APT) group based in China, known as Jewelbug, is engaged in both international cyber espionage and cryptocurrency theft, according to a recent report by Symantec, with further coverage provided by Dark Reading. Jewelbug operates a single, custom command-and-control (C2) panel to manage its dual operations. The group utilizes three primary custom malware implants: Antino (Windows backdoor), ClientKing (Linux backdoor), and a browser extension named "PDF Viewer." This extension is particularly versatile, capable of stealing cookies, session tokens, and screenshots, injecting JavaScript, and potentially replacing cryptocurrency addresses during transactions. For its cryptocurrency fraud operations, Jewelbug creates thousands of fake cryptocurrency and betting websites, boosted by click-fraud bots and sophisticated filtering to target victims. The group has compromised government, military, and telecommunications organizations in Asia and the Middle East, as well as a major U.S. industrial manufacturer. Symantec researchers discovered hundreds of thousands of stolen cookies and thousands of login credentials, indicating a significant number of victims. The scale and nature of Jewelbug's activities suggest it is likely operating on behalf of a Chinese state agency or for its own gain with the intent to sell stolen information to government contacts. Source: Dark Reading SC Staff Related Threat Intelligence ExfilSquad targets 13 organizations, uses torrents for data distribution SC Staff August 11, 2026 The group, which extorts victims by threatening to publish stolen data rather than using ransomware, has expanded its operations, according to a recent report by Resecurity. Threat Intelligence Hacktivist group Head Mare exploits TrueConf vulnerabilities to deliver backdoors SC Staff August 10, 2026 The attackers leverage vulnerabilities, tracked as KLCERT-26-057 and KLCERT-26-058, to execute arbitrary code and gain elevated privileges on the server, according to Kaspersky. Black Hat Fortra’s Josh Davies on the evolving exploitation of trust SC Staff August 7, 2026 Davies shares insights from original FIRE research, while also digging into trends. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms DNS Spoofing Deauthentication Attack Defacement Denial of Service Dictionary Attack Distributed Scans Domain Hijacking DumpSec Dumpster Diving Google Hacking You can skip this ad in 5 seconds

Share this article